TriDComm Built-in FTP Server Directory Traversal Vulnerability
BID:11343
Info
TriDComm Built-in FTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 11343 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1583 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Luigi Auriemma <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Lajos Kelemen TriDComm 1.3 Lajos Kelemen TriDComm 1.2 |
| Not Vulnerable: | |
Discussion
TriDComm Built-in FTP Server Directory Traversal Vulnerability
It is reported that TriDComm is susceptible to a directory traversal vulnerability in its built-in FTP server. The FTP server is not enabled by default.
This vulnerability allows attackers to write, or access files contained outside of the configured document root of the affected FTP server with the privileges of the affected process. This may allow them to overwrite critical files, resulting in denial of service conditions, or assist them in full system compromise. They may also retrieve the contents of potentially sensitive files, aiding them in further attacks.
This vulnerability is reported to exist in versions 1.2 and 1.3 of the package.
It is reported that TriDComm is susceptible to a directory traversal vulnerability in its built-in FTP server. The FTP server is not enabled by default.
This vulnerability allows attackers to write, or access files contained outside of the configured document root of the affected FTP server with the privileges of the affected process. This may allow them to overwrite critical files, resulting in denial of service conditions, or assist them in full system compromise. They may also retrieve the contents of potentially sensitive files, aiding them in further attacks.
This vulnerability is reported to exist in versions 1.2 and 1.3 of the package.
Exploit / POC
TriDComm Built-in FTP Server Directory Traversal Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
TriDComm Built-in FTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TriDComm Built-in FTP Server Directory Traversal Vulnerability
References:
References:
- TriDComm Home Page (Lajos Kelemen)
- Directory traversal in Tridcomm 1.3 (Luigi Auriemma
)